A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escalation to the administrative level due to the usage of component vendor Docker images running with root permissions. Exploiting this misconfiguration leads to the fact that an attacker can gain administrative control. over the whole system.
History

Tue, 19 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Sick Ag
Sick Ag incoming Goods Suite
CPEs cpe:2.3:a:sick_ag:incoming_goods_suite:*:*:*:*:*:*:*:*
Vendors & Products Sick Ag
Sick Ag incoming Goods Suite
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 19 Nov 2024 13:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escalation to the administrative level due to the usage of component vendor Docker images running with root permissions. Exploiting this misconfiguration leads to the fact that an attacker can gain administrative control. over the whole system.
Title SICK Incoming Goods Suite privilege escalation vulnerability
Weaknesses CWE-250
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SICK AG

Published: 2024-11-19T13:13:00.565Z

Updated: 2024-11-19T14:13:07.706Z

Reserved: 2024-11-11T09:08:53.239Z

Link: CVE-2024-11075

cve-icon Vulnrichment

Updated: 2024-11-19T14:13:03.268Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-19T14:15:17.340

Modified: 2024-11-19T21:57:32.967

Link: CVE-2024-11075

cve-icon Redhat

No data.